FreeFind your cybersecurity gaps with a free GAPZe assessmentStart now

Cybersecurity

NIST CSF 2.0 Implementation: A Practical Guide From Govern Up

Isometric illustration of six coloured blocks arranged in a ring around a red shield, representing the six NIST CSF 2.0 functions, in Anvay's red and stone colours

NIST CSF 2.0 implementation means using the NIST Cybersecurity Framework 2.0 to describe the security outcomes you have today, decide the outcomes you need, and close the gap in a planned order. It is voluntary and suits organisations of any size or sector. The practical next step is to set up governance first, then build an honest Current Profile against the six functions.

TL;DR

  • Start with the Govern function: name an executive owner, agree risk appetite and set supply chain expectations before you score anything.
  • Build a Current Profile against the 22 categories in 2 to 4 weeks, with evidence and a named owner for every outcome.
  • Set a Target Profile from business risk, not from a wish to “score high”. Choose a Tier per profile to describe rigour, not maturity.
  • Turn gaps into a prioritised 6 to 12 month action plan with owners, dates and budget decisions agreed by leadership.
  • Report progress to the board each quarter and refresh both profiles at least once a year, or after a major change or incident.

What is the NIST Cybersecurity Framework 2.0 and why does it matter?

The NIST Cybersecurity Framework 2.0 (CSF 2.0) is guidance from the US National Institute of Standards and Technology, published as NIST CSWP 29 on 26 February 2024. It replaced version 1.1 from 2018. The framework is a taxonomy of high-level cybersecurity outcomes: it tells you what good looks like, not how to achieve it. That “how” lives in linked resources and in the controls you choose.

Version 1.1 was written with critical infrastructure in mind. CSF 2.0 is explicitly aimed at organisations of any size, sector or maturity, which is why it is now common in UK firms with US customers, investors or parent companies, and in boards that want a single, plain-language view of cyber risk. It is not a certifiable standard. Nobody “passes” NIST CSF; you use it to understand, prioritise and communicate risk.

The framework has three parts that matter for implementation:

  • The CSF Core: six functions, 22 categories and 106 subcategories describing outcomes.
  • Organizational Profiles: a Current Profile (where you are) and a Target Profile (where you need to be), expressed in Core outcomes.
  • Tiers: four levels describing how rigorous your cyber risk governance and management practices are.

Around these, NIST publishes supporting resources: Implementation Examples (short, action-oriented illustrations of how to achieve each subcategory), Informative References (mappings from the Core to other standards and controls, such as NIST SP 800-53 or ISO/IEC 27001), and Quick-Start Guides on topics including small business, profiles, tiers and supply chain risk.

What are the six NIST CSF functions?

The six NIST CSF functions are Govern, Identify, Protect, Detect, Respond and Recover. NIST draws Govern at the centre of a wheel because it informs how the other five are carried out. Here they are in plain English, with the categories in each.

  • Govern (GV): organisational context, risk management strategy, roles and responsibilities, policy, oversight and cybersecurity supply chain risk management.
  • Identify (ID): asset management, risk assessment and improvement.
  • Protect (PR): identity management, authentication and access control; awareness and training; data security; platform security; and technology infrastructure resilience.
  • Detect (DE): continuous monitoring and adverse event analysis.
  • Respond (RS): incident management, analysis, reporting and communication, and mitigation.
  • Recover (RC): executing the incident recovery plan and recovery communication.
The six NIST CSF 2.0 functions with example outcomes and evidence
FunctionExample outcomeTypical evidence
GovernCyber risk appetite is agreed and roles are assigned at leadership levelBoard-approved risk statement, RACI, security policy, supplier security requirements
IdentifyHardware, software, data and services are inventoried and risks are assessedAsset register, data map, risk register with owners and review dates
ProtectAccess is limited to authorised users and data is protected at rest and in transitMFA coverage report, joiner-mover-leaver records, encryption settings, patching metrics
DetectNetworks, endpoints and services are monitored for adverse eventsLogging coverage, alert triage records, EDR or SIEM dashboards
RespondIncidents are triaged, contained and reported to the right partiesIncident response plan, incident tickets, tabletop exercise reports
RecoverSystems and data are restored to agreed objectives and stakeholders are kept informedBackup restore tests, recovery time results, recovery communication templates

What is the NIST CSF Govern function, and why is it new?

Govern is the main structural change in CSF 2.0. In version 1.1, governance outcomes were scattered across Identify. Pulling them into their own function makes a clear point: cybersecurity is an enterprise risk that leadership owns, not a technical topic delegated to IT.

In practice, the NIST CSF Govern function asks whether your organisation has:

  • Understood its mission, stakeholders, and legal, regulatory and contractual requirements (Organizational Context).
  • Set risk appetite and tolerance, and linked cyber risk to enterprise risk management (Risk Management Strategy).
  • Assigned accountability, authority and resources, including at executive level (Roles, Responsibilities, and Authorities).
  • Written, communicated and enforced policy (Policy).
  • Reviewed whether the strategy is working and adjusted it (Oversight).
  • Managed the cyber risk that comes from suppliers and partners (Cybersecurity Supply Chain Risk Management).

Supply chain risk is the category many organisations find hardest. If that is a gap for you, our guide to third-party risk management covers how to tier suppliers and set proportionate requirements.

NIST CSF profiles and tiers explained

NIST CSF profiles are the working documents of any implementation. A Current Profile records which Core outcomes you achieve now, and how well. A Target Profile records which outcomes you want to achieve and to what degree, reflecting your mission, risk appetite, obligations and threats. The difference between the two is your gap, and it is the basis for your action plan. NIST also describes Community Profiles: baseline Target Profiles shared by a sector or community, which you can adopt and tailor.

A profile does not have to cover every subcategory with equal depth. Mark the outcomes that matter most, note which are out of scope, and record why. That reasoning is what makes the profile defensible later.

NIST CSF tiers describe how rigorous your cyber risk governance and management practices are. The four Tiers are:

  1. Tier 1 – Partial: ad hoc, reactive, with limited awareness of cyber risk at organisational level.
  2. Tier 2 – Risk Informed: management approves risk practices, but they may not be organisation-wide policy.
  3. Tier 3 – Repeatable: practices are formally approved as policy and regularly updated as risks and requirements change.
  4. Tier 4 – Adaptive: practices adapt based on lessons learned and predictive indicators, and cyber risk is part of organisational culture.

Tiers are applied to profiles to give context. They are not a scorecard, and NIST does not expect every organisation to aim for Tier 4. A small professional services firm may be well served at Tier 2 or 3; a payments provider is likely to need more.

NIST CSF for small business: where to start

NIST CSF for small business does not require a full programme on day one. NIST’s Small Business Quick-Start Guide is written for organisations with modest or no cybersecurity plans, and it suggests starting with the basics in each function: know your assets, protect accounts and data, know how you would spot and handle an incident, and know how you would recover.

For UK SMEs, it is often sensible to pair the CSF with Cyber Essentials. Cyber Essentials gives you a certified baseline of technical controls (firewalls, secure configuration, user access control, malware protection and security update management), and the CSF gives you the governance and response outcomes that Cyber Essentials does not cover.

How to implement NIST CSF 2.0: a step-by-step checklist

This is the sequence we recommend for a first NIST CSF 2.0 implementation. It follows NIST’s own approach of scoping, profiling, analysing gaps and acting, with Govern placed first.

  1. Define scope and mission. Decide whether the profile covers the whole organisation, a business unit or a specific service. Record the mission, key stakeholders, and legal, regulatory and contractual obligations.
  2. Set up Govern first. Name an executive sponsor and a day-to-day owner. Agree risk appetite and tolerance. Confirm how cyber risk feeds into enterprise risk reporting, and set baseline expectations for critical suppliers.
  3. Create the Current Profile. Work through the 22 categories with the people who run each area. For each outcome, record status, evidence and an owner. Use Implementation Examples to calibrate what “achieved” means.
  4. Set the Target Profile. Decide which outcomes matter most given your risk appetite and threats, and choose the Tier you are aiming for. Consider any relevant Community Profile.
  5. Run a gap analysis and build a prioritised action plan. Rank gaps by risk reduction, effort and dependency. Assign owners, dates and resources, and get leadership to approve the plan and its trade-offs.
  6. Implement. Use Informative References to pick controls from frameworks you already use, such as ISO/IEC 27001 Annex A or the NCSC Cyber Assessment Framework, rather than inventing new ones.
  7. Measure and report to the board. Track a small set of measures linked to the Target Profile, and report progress, residual risk and decisions needed each quarter.
  8. Review on a cycle. Refresh the Current Profile at least annually and after significant change, such as an acquisition, a new system or a major incident. Adjust the Target Profile as the business changes.

How long does a NIST CSF assessment and implementation take?

A first NIST CSF assessment, covering scoping, Govern set-up and the Current Profile, typically takes 3 to 6 weeks for a small or mid-sized organisation. Setting the Target Profile and agreeing the action plan usually adds 2 to 4 weeks. Closing the gaps is a programme in its own right, commonly running 6 to 18 months depending on the starting point.

The main effort drivers are:

  • Scope: one service or the whole organisation, and how many sites, entities and cloud environments are involved.
  • Existing documentation: an asset register, risk register and policies shorten the Current Profile considerably.
  • Leadership availability: Govern decisions stall without time from executives.
  • Supplier complexity: many critical or poorly understood suppliers lengthen supply chain work.
  • Technical debt: legacy systems, weak identity controls or limited logging make Protect and Detect gaps slower to close.
  • Overlap with other frameworks: if you already hold ISO/IEC 27001 or Cyber Essentials, much of the evidence exists.

Common NIST CSF 2.0 implementation mistakes

  • Treating Tiers as maturity grades. Tiers describe the rigour of governance and risk management, not a score per control. Averaging subcategory ratings into a “Tier 2.7” misreads the framework and misleads the board.
  • Skipping Govern. Jumping straight to technical controls produces a long list of fixes with no agreed risk appetite to prioritise them, and no executive owner to fund them.
  • Profiles without owners. A profile that no named person maintains is out of date within months. Every category needs an owner and a review date.
  • Scoring without evidence. Self-assessment is a fine start, but outcomes marked “achieved” should point to something you could show a reviewer.
  • Aiming for everything. A Target Profile that demands the top level on every outcome is a wish list, not a plan.
  • Running it as a one-off. The CSF is designed for a continuous cycle. A single assessment filed away delivers little.

How does NIST CSF 2.0 relate to ISO 27001 and Cyber Essentials?

The three fit together rather than compete. ISO/IEC 27001 is a certifiable management system standard: an accredited certification body audits your ISMS. Cyber Essentials is a UK government-backed certification of five technical control areas. NIST CSF 2.0 is a voluntary outcomes framework with no certification, which makes it a strong tool for prioritising and for reporting to boards. Many organisations use the CSF as the common language and map ISO 27001 controls to it through NIST’s Informative References. Our comparison of NIST CSF vs ISO 27001 goes into the differences in more detail.

How Anvay approaches NIST CSF 2.0 implementation

We keep the work in four steps, with governance at the front and evidence throughout.

  1. Govern and scope. We agree scope, mission and obligations with leadership, confirm owners and draft risk appetite and supplier expectations.
  2. Build your Current Profile. We work through the six functions with your team and record status, evidence and owners. GAPZe has a live NIST CSF 2.0 pack that gives an indicative Current Profile from self-reported answers, which is a fast way to start the conversation. It is a readiness screening, not an audit opinion.
  3. Set the Target Profile and gaps. We help you choose target outcomes and Tiers that match your risk appetite, then rank the gaps into a prioritised roadmap.
  4. Act, measure and review. We support delivery, set up board reporting and agree a review cycle so the profiles stay current.
Anvay's four-step NIST CSF 2.0 approach: 1. Govern and scope; 2. Build your Current Profile; 3. Set the Target Profile and gaps; 4. Act, measure and review
Anvay’s four-step approach puts governance first and keeps both profiles owned and current.

One practical takeaway for NIST CSF 2.0 implementation

Before you score a single Protect or Detect outcome, hold one meeting with leadership to agree who owns cyber risk and what level of disruption is unacceptable. Everything else in a NIST CSF 2.0 implementation, from the Target Profile to the order of fixes, depends on those two answers. Get them on paper first and the rest of the work becomes a sequence of informed decisions rather than a long list of controls.

— Achal, Anvay

Anvay services for NIST CSF 2.0

Start with a free GAPZe assessment using the NIST CSF 2.0 pack for an indicative Current Profile, a free PDF report and a free 30-minute 1:1 to talk through the results. From there, our cyber assessments validate the profile with evidence, our GRC and risk service helps set up Govern, risk appetite and board reporting, and our fractional CISO service provides ongoing leadership to run the roadmap. If incident readiness is a gap, a tabletop exercise tests your Respond and Recover outcomes. Talk to us about your NIST CSF 2.0 implementation.

FAQ

Is NIST CSF 2.0 mandatory?

No. The NIST Cybersecurity Framework 2.0 is voluntary guidance. Some customers, regulators or contracts may expect you to align with it, but NIST does not certify organisations against it and there is no formal audit. Most organisations adopt it to prioritise cyber risk and to give leadership a clear, consistent way to track progress over time.

How do you start a NIST CSF 2.0 implementation?

Start with the Govern function: agree scope, name an executive owner, set risk appetite and confirm supplier expectations. Then build a Current Profile across the 22 categories with evidence and owners, set a Target Profile, and turn the gaps into a prioritised action plan approved by leadership. A first pass typically takes a few weeks.

What is the difference between NIST CSF profiles and tiers?

Profiles describe outcomes: the Current Profile shows what you achieve now and the Target Profile shows what you need. Tiers describe how rigorous your cyber risk governance and management practices are, from Partial to Adaptive. Tiers give context to a profile; they are not a maturity score for individual controls.

Is NIST CSF suitable for a small business?

Yes. CSF 2.0 is designed for organisations of any size, and NIST publishes a Small Business Quick-Start Guide for firms with modest or no cybersecurity plans. Small businesses can focus on a handful of high-value outcomes in each function and, in the UK, pair the framework with Cyber Essentials for a certified technical baseline.

Can you be certified against NIST CSF 2.0?

No. There is no NIST certification for the CSF. Organisations that need certification usually pursue ISO/IEC 27001 through an accredited certification body, or Cyber Essentials in the UK, and use the CSF alongside them. Tools such as GAPZe give an indicative readiness view based on self-reported answers, not a certification.

Sources

Primary references and standards: this article draws on NIST CSWP 29 and NIST’s CSF 2.0 Quick-Start Guides and Informative References resources.

Back to all insights

Make your next step clearer.

Tell us what you are working on or where you feel unsure. We will talk it through with you and suggest practical support that fits.

Discuss your requirements